Executive brief
A vulnerability in Google Chrome for Android could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by mimicking legitimate system or browser messages. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
A UI spoofing vulnerability exists in the Messages component of Google Chrome for Android. The flaw stems from an inappropriate implementation that allows a remote attacker to manipulate the user interface via a specially crafted HTML page. By enticing a user to visit a malicious website, an attacker could display deceptive UI elements to facilitate phishing or other social engineering attacks. The issue is resolved in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed